← Back
CWE-79

47,450 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,450)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mcafee
1Epolicy Orchestrator
Jun 17, 2026
Mar 23, 2022
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the...Show more
A cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link. This would lead to limited ability to alter some information in ePO due to the area of the User Interface the vulnerability is present in.Show less
1Mcafee
1Epolicy Orchestrator
Jun 17, 2026
Mar 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by conv...Show more
A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO due to the area of the User Interface the vulnerability is present in.Show less
1Enhanced Github Project
1Enhanced Github
Jun 17, 2026
Mar 22, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross Site Scripting (XSS) vulnerabililty exists in enhanced-github v5.0.11 via the file name parameter.
1Bigantsoft
1Bigant Server
Jul 9, 2026
Mar 21, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability.
1Wpdevart
1Pricing Table Builder
Jun 17, 2026
Mar 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Accesspressthemes
1Ap Mega Menu
Jun 17, 2026
Mar 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Tms Outsource
1Amelia
Jun 17, 2026
Mar 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Ait Pro
1Bulletproof Security
Jun 17, 2026
Mar 21, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capabil...Show more
The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
13dflipbook
13d Flipbook
Jun 17, 2026
Mar 21, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to...Show more
The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads in all pages with a 3d flipbook.Show less
1Webnus
1Modern Events Calendar Lite
Jun 17, 2026
Mar 21, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scr...Show more
The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacksShow less
1Squirrly
1Seo Plugin By Squirrly Seo
Jun 17, 2026
Mar 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
1Primekey
1Signserver
Jun 17, 2026
Mar 21, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS was identified in the Admin Web interface of PrimeKey SignServer before 5.8.1. JavaScript code must be used in a worker name before a Generate CSR request. Only an administrator can update a worker name.
1Hexoeditor Project
1Hexoeditor
Jun 17, 2026
Mar 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
HexoEditor 1.1.8 is affected by Cross Site Scripting (XSS). By putting a common XSS payload in a markdown file, if opened with the app, will execute several times.
1Otrs
1Otrs
Jun 17, 2026
Mar 21, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package manager. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.32 and pr...Show more
Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package manager. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.32 and prior versions, 8.0.x version: 8.0.19 and prior versions.Show less
1Eova
1Eova
Jun 17, 2026
Mar 20, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability in the Add a Button function of Eova v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the button name text box.
1Tms Project
1Tms
Jun 17, 2026
Mar 20, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
TMS v2.28.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /TMS/admin/setting/mail/createorupdate.
1Html Js
1Doracms
Jun 17, 2026
Mar 20, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Mar 18, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by default.
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Mar 18, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in MISP before 2.4.156. A malicious site administrator could store an XSS payload in the custom auth name. This would be executed each time the administrator modifies a user.
1Wp Downloadmanager Project
1Wp Downloadmanager
Jun 17, 2026
Mar 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_u...Show more
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_url.Show less